EN

Vulnerabilità Cisco

6642 CVE

CVE-2018-0149
Media 4.8

A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross…

cisco integrated_management_controller_supervisor
0.01EPSS
CVE-2014-2146
Media 6.5

The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via spoof…

cisco ios · cisco ios_xe
0.01EPSS
CVE-2020-3585
Media 5.3

A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive infor…

cisco adaptive_security_appliance_software · cisco firepower_threat_defense · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2016-1450
Alta 7.5

Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715.

cisco webex_meetings_server
0.01EPSS
CVE-2015-0620
Media 4.0

The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494.

cisco telepresence_management_suite
0.01EPSS
CVE-2021-1366
Alta 7.8

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is …

cisco anyconnect_secure_mobility_client
0.01EPSS
CVE-2006-4352
Media 5.0

The ArrowPoint cookie functionality for Cisco 11000 series Content Service Switches specifies an internal IP address if the administrator does not specify a string option, which allows remote attackers to obtain sensitive information.

cisco content_services_switch_11000
0.01EPSS
CVE-2016-1440
Media 5.3

The proxy process on Cisco Web Security Appliance (WSA) devices through 9.1.0-070 allows remote attackers to cause a denial of service (CPU consumption) by establishing an FTP session and then improperly terminating the control connection after a file transfer…

cisco web_security_appliance
0.01EPSS
CVE-2019-1669
Alta 8.6

A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) condition. The vulnerabilit…

cisco secure_firewall_threat_defense
0.01EPSS
CVE-2014-8017
Media 5.0

The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.

cisco identity_services_engine_software
0.01EPSS
CVE-2014-2194
Media 6.8

system/egain/chat/entrypoint in Cisco Unified Web and E-mail Interaction Manager 9.0(2) allows remote attackers to have an unspecified impact by injecting a spoofed XML external entity.

cisco unified_web_and_e-mail_interaction_manager
0.01EPSS
CVE-2021-34741
Alta 7.5

A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due…

cisco asyncos
0.01EPSS
CVE-2021-1222
Alta 8.1

A vulnerability in the web-based management interface of Cisco Smart Software Manager Satellite could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management inte…

cisco smart_software_manager_on-prem
0.01EPSS
CVE-2015-0628
Media 5.0

The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP method, aka Bug ID CSCus79174.

cisco web_security_appliance
0.01EPSS
CVE-2014-2195
Media 4.3

Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote attackers to gain role privileges by leveraging group-name simi…

cisco asyncos · cisco content_security_management_appliance · cisco email_security_appliance_firmware
0.01EPSS
CVE-2013-5561
Media 5.0

The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering, which allows remote attackers to bypass intended policy restrictions via unspecified vectors, aka Bug ID CSCu…

cisco adaptive_security_appliance_cx_context-aware_security_software
0.01EPSS
CVE-2002-2139
Media 6.4

Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.

cisco pix_firewall_software
0.01EPSS
CVE-2020-3160
Media 5.3

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of XMPP conferencing applications. Other ap…

cisco meeting_server
0.01EPSS
CVE-2016-6396
Media 5.3

Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP headers, aka Bug ID CSCuz44482.

cisco firesight_system_software
0.01EPSS
CVE-2023-20040
Media 5.5

A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the atta…

cisco network_services_orchestrator
0.01EPSS
CVE-2022-20889
Media 4.7

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe…

cisco application_extension_platform · cisco rv110w_firmware · cisco rv130_firmware · cisco rv130w_firmware · e altri 1
0.01EPSS
CVE-2017-6764
Media 5.4

A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affe…

cisco adaptive_security_appliance_software
0.01EPSS
CVE-2017-6661
Media 6.1

A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of…

cisco content_security_management_appliance · cisco email_security_appliance
0.01EPSS
CVE-2015-0746
Media 5.0

The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022.

cisco secure_access_control_server
0.01EPSS
CVE-2022-20822
Alta 7.1

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied in…

cisco identity_services_engine
0.01EPSS